** blue screen, missing registry, & virus.. Help pls.. **

Discussion in 'Malware Help (A Specialist Will Reply)' started by GamerPrincess, Aug 27, 2013.

  1. GamerPrincess

    GamerPrincess Private E-2

    i'm trying to fix my desktop now.. i was helped a few months ago with my laptop.. & i absolutely loved the help from everyone on here.. thanks again.. the thing with this computer is.. it crashes randomly.. the screen turns blue.. and counts down.. super annoying especially when im in the middle of doing things.. also in the Unistall Menu.. it has programs that CAN NOT be deleted.. there is a virus.. or something on here.. i've been told before.. but costs way into the hundreds to fix.. also when it starts up and loads.. it has an error message as follows;
    !DESKTOP!
    COULD NOT LOAD OR RUN 'C:\WINDOWS\TEMP\csrss.exe' specified in the registry. Make sure files exists on your computer or remove the references to it in the registry.

    can some one help please.. i am going to start the READ ME part of this now.. thank you!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Once you complete this and attach the requested logs, we can start to help you. ;)
     
  3. GamerPrincess

    GamerPrincess Private E-2

    I have the RK log.. doing the Malwarebytes now..
     

    Attached Files:

    Last edited by a moderator: Aug 28, 2013
  4. GamerPrincess

    GamerPrincess Private E-2

    i did my best.. hopefully you can tell me what is wrong.. =) THANKS AGAIN!! =)
     

    Attached Files:

    Last edited by a moderator: Aug 28, 2013
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on the info in your logs, I really would prefer to see the requested log from Hitman Pro before continuing; however I will give you one starting fix to run anyway but this may not be a complete fix.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com?o=14196&l=dis
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=aln1&s={searchTerms}&f=4
    R3 - URLSearchHook: (no name) - {00000000-6E41-4FD3-8538-502F5495E5FC} - (no file)
    O2 - BHO: (no name) - {00103B5F-2F17-444A-980C-2A6FA997C230} - C:\Windows\system32\eapphost32.dll (file missing)
    O2 - BHO: (no name) - {0019BA46-6DC9-4E36-9BD9-FCC9BA52E91e} - C:\Windows\system32\dxgi32.dll (file missing)
    O2 - BHO: (no name) - {002F0C47-C507-4C43-9F57-31A661E14BB0} - C:\Windows\system32\GameUXLegacyGDFs32.dll (file missing)
    O2 - BHO: (no name) - {005CF643-2F98-4DCF-ABA3-B8B3ED0C53D1} - C:\Windows\system32\dskquoui32.dll (file missing)
    O2 - BHO: (no name) - {006B6D90-C28D-4707-8245-27C0325DA7Cf} - C:\Windows\system32\D3DX9_4232.dll (file missing)
    O2 - BHO: (no name) - {00BA9D63-B82D-4BFE-B251-D4D150508A75} - C:\Windows\system32\dsdmo32.dll (file missing)
    O2 - BHO: (no name) - {00FF5946-AFED-4FAA-8C19-15ABE849F627} - C:\Windows\system32\browseui32.dll (file missing)
    O2 - BHO: (no name) - {012772AB-9990-494A-958B-423BA8A4D962} - C:\Windows\system32\fdSSDP32.dll (file missing)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: P2P Max Toolbar - {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - C:\Program Files\P2P_Max\tbP2P0.dll
    O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    O2 - BHO: Updater For Simppull Toolbar - {C4B8BAB4-1667-11DF-A242-BA9455D89593} - C:\Program Files\simppulltoolbar\auxi\simppulltoolbAu.dll (file missing)
    O2 - BHO: TBSB07898 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll (file missing)
    O3 - Toolbar: P2P Max Toolbar - {72ae8426-3b8d-4ead-b191-8d0ad1c62158} - C:\Program Files\P2P_Max\tbP2P0.dll
    O3 - Toolbar: Coupons.com CouponBar - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - C:\Program Files\Coupons.com CouponBar\tbcore3.dll (file missing)
    O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    O9 - Extra button: (no name) - {53F6FCCD-9E22-4d71-86EA-6E43136192AB} - (no file)
    O9 - Extra button: (no name) - {925DAB62-F9AC-4221-806A-057BFB1014AA} - (no file)
    O23 - Service: System Event Notification Service (SENS32) - Unknown owner - C:\Windows\system32\dmusic32.exe (file missing)

    After clicking Fix, exit HJT.

    Now uninstall the below software:
    Java(TM) 6 Update 37
    P2P_Max Toolbar

    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    :Services
    SENS32
     
    :Files
    C:\Windows\$NtUninstallKB18044$
    C:\Windows\TEMP\csrss.exe
    C:\Users\STEVEN\AppData\Roaming\dwm.exe
    C:\Users\STEVEN\AppData\Roaming\Microsoft\Windows\Templates\4f6h0p84a5yu63tbhj5in141h
    C:\Users\STEVEN\Desktop\zcmxmdwvzr.tmp
    C:\Program Files\P2P_Max
    C:\Program Files\simppulltoolbar
    C:\Program Files\Coupons.com CouponBar
    C:\Windows\Temp\*.*
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72ae8426-3b8d-4ead-b191-8d0ad1c62158}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{72ae8426-3b8d-4ead-b191-8d0ad1c62158}"=-
    
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes]
    "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}]
    "URL"="[URL]http://start.facemoods.com/?a=aln1&s={searchTerms}&f=4[/URL]"
    "DisplayName"="Facemoods Search"
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A59}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs]
    "Tabs"="res://ieframe.dll/tabswelcome.htm"
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXTlog
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 28, 2013
  6. GamerPrincess

    GamerPrincess Private E-2

    im not sure which mg files u wanted.. i could not find the one from the GetLogs run.. =[
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just what I asked for and what you attached.... the MGlogs.zip file.

    Round 2. Make sure you tell me how things are running this time after the fix.



    Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
     
    :Files
    C:\Program Files\Babylon
    C:\Program Files\Conduit
    C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
    C:\Users\wormie\AppData\Local\Conduit
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\escort.DLL]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{BDB69379-802F-4eaf-B541-F8DE92DD98DB}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2EECD738-5844-4a99-B4B6-146BF802613B}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44b0-A826-84C829536E93}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Prod.cap]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}]
    [-HKEY_USERS\S-1-5-21-3028501158-2239877175-2436331423-1000\Software\Conduit]
    [-HKEY_USERS\S-1-5-21-3028501158-2239877175-2436331423-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}]
    [-HKEY_USERS\S-1-5-21-3028501158-2239877175-2436331423-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large http://forums.majorgeeks.com/chaslang/images/MoveIt!.png button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  8. GamerPrincess

    GamerPrincess Private E-2

    otay i did everything you asked.. the computer seems to be loading faster.. except the internet keeps crashing.. im not sure whats causing it.. im only on this site.. so far ive left the comp on over night and no blue screen.. yay!! thank you!!
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have a few services related to your Windows Firewall that are broken.
    Now run the C:\MGtools\NetFWfix.bat file by using right click and select Run As Administrator. This will run quickly and you may notice a quick flash of a black command prompt window. Approve any prompts that you may get ask to allow this to run.

    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.
    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not reboot, then reboot it yourself now.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  10. GamerPrincess

    GamerPrincess Private E-2

    otay.. done with all that.. i couldn't leave the comp there.. i had to push run for a few things.. didn't take long.. about 40 mins.. so far so good.. has not reset once with the blue screen.. yay!! question.. how do you take off toolbars from the internet.. on the top.. i can not find it in the uninstall bar..
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the follow up log I requested.

    Which toolbar(s) are you referring too and in which browser?
     
  12. GamerPrincess

    GamerPrincess Private E-2

    i thought i did.. Lol.. Sorry.. I figured it out about the toolbars... Thank you!!
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    There are a couple of items we attempted to remove earlier that did not completely go away. Let's try the below.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)
    O3 - Toolbar: (no name) - {95B7759C-8C7F-4BF1-B163-73684A933233} - (no file)

    After clicking Fix, click the Scan button again and see if they are really gone. Then you can exit HJT. Let me know the results
     
  14. GamerPrincess

    GamerPrincess Private E-2

    it deleted them both now.. anything else?? or should i be good now?? did it fix the problems in the registry???
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  16. GamerPrincess

    GamerPrincess Private E-2

    FINISHED!! okay another question.. there is an application called ringtone media in my uninstall page.. well I've tried to to uninstall it on numerous accounts... and it will not delete.. how can i get rid of it??????????
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For non-malware issues, you really need to post in the Software Forum, but you can try using the below to uninstall it.

    Revo Uninstaller 1.95
     
  18. GamerPrincess

    GamerPrincess Private E-2

    Is there something else? I haven't had net access to this computer in quite some time.. hope you can still help.. =)
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm sorry but this thread is almost 4 months old now since my last post to you.

    Not sure what you mean. You did not say this 4 months ago when I gave you final steps. And at that time, all malware was removed. If you are having problems now, you will have to run the READ & RUN ME FIRST so that we can make sure that you have not reinfected the PC again. But please tell me what you mean by "haven't had net access to this computer". Are you trying to remotely login to it?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds